Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
200

Scientific Linux: CVE-2007-4571 Moderate: ALSA Memory Issue

Important: kernel security update. Date: Mon, 3 Dec 2007 12:04:56 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for kernel on SL5.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Important: kernel security update Issue date: 2007-11-29 CVE Names: CVE-2007-4571 CVE-2007-4997 CVE-2007-5494 These new kernel packages contain fixes for the following security issues: A memory leak was found in the Red Hat Content Accelerator kernel patch. A local user could use this flaw to cause a denial of service (memory exhaustion). (CVE-2007-5494, Important) A flaw was found in the handling of IEEE 802.11 frames affecting several wireless LAN modules. In certain circumstances, a remote attacker could trigger this flaw by sending a malicious packet over a wireless network and cause a denial of service (kernel crash). (CVE-2007-4997, Important). A flaw was found in the Advanced Linux Sound Architecture (ALSA). A local user who had the ability to read the /proc/driver/snd-page-alloc file could see portions of kernel memory. (CVE-2007-4571, Moderate). In addition to the security issues described above, several bug fixes preventing possible memory corruption, system crashes, SCSI I/O fails, networking drivers performance regression and journaling block device layer issue were also included. SL 5.x SRPMS: kernel-2.6.18-53.1.4.el5.src.rpm i386: kernel-2.6.18-53.1.4.el5.i686.rpm kernel-debug-2.6.18-53.1.4.el5.i686.rpm kernel-debug-devel-2.6.18-53.1.4.el5.i686.rpm kernel-devel-2.6.18-53.1.4.el5.i686.rpm kernel-doc-2.6.18-53.1.4.el5.noarch.rpm kernel-headers-2.6.18-53.1.4.el5.i386.rpm kernel-PAE-2.6.18-53.1.4.el5.i686.rpm kernel-PAE-devel-2.6.18-53.1.4.el5.i686.rpm kernel-xen-2.6.18-53.1.4.el5.i686.rpm kernel-xen-devel-2.6.18-53.1.4.el5.i686.rpm Dependancies: kernel-module-fuse-2.6.18-53.1.4.el5-2.6.3-1.sl5.i686.rpm kernel-module-fuse-2.6.18-53.1.4.el5PAE-2.6.3-1.sl5.i686.rpm kernel-module-fuse-2.6.18-53.1.4.el5xen-2.6.3-1.sl5.i686.rpm kernel-module-ndiswrapper-2.6.18-53.1.4.el5-1.41-1.SL.i686.rpm kernel-module-ndiswrapper-2.6.18-53.1.4.el5PAE-1.41-1.SL.i686.rpm kernel-module-ndiswrapper-2.6.18-53.1.4.el5xen-1.41-1.SL.i686.rpm kernel-module-openafs-2.6.18-53.1.4.el5-1.4.4-42.SL5.i686.rpm kernel-module-openafs-2.6.18-53.1.4.el5-debuginfo-1.4.4-42.SL5.i686.rpm kernel-module-openafs-2.6.18-53.1.4.el5PAE-1.4.4-42.SL5.i686.rpm kernel-module-openafs-2.6.18-53.1.4.el5PAE-debuginfo-1.4.4-42.SL5.i686.rpm kernel-module-openafs-2.6.18-53.1.4.el5xen-1.4.4-42.SL5.i686.rpm kernel-module-openafs-2.6.18-53.1.4.el5xen-debuginfo-1.4.4-42.SL5.i686.rpm kernel-module-r1000-2.6.18-53.1.4.el5-1.05-1.sl.i686.rpm kernel-module-r1000-2.6.18-53.1.4.el5PAE-1.05-1.sl.i686.rpm kernel-module-r1000-2.6.18-53.1.4.el5xen-1.05-1.sl.i686.rpm kmod-gfs-0.1.19-7.el5.1.i686.rpm kmod-gfs-PAE-0.1.19-7.el5.1.i686.rpm kmod-gfs-xen-0.1.19-7.el5.1.i686.rpm x86_64: kernel-2.6.18-53.1.4.el5.x86_64.rpm kernel-debug-2.6.18-53.1.4.el5.x86_64.rpm kernel-debug-devel-2.6.18-53.1.4.el5.x86_64.rpm kernel-devel-2.6.18-53.1.4.el5.x86_64.rpm kernel-doc-2.6.18-53.1.4.el5.noarch.rpm kernel-headers-2.6.18-53.1.4.el5.x86_64.rpm kernel-xen-2.6.18-53.1.4.el5.x86_64.rpm kernel-xen-devel-2.6.18-53.1.4.el5.x86_64.rpm Dependancies: kernel-module-fuse-2.6.18-53.1.4.el5-2.6.3-1.el5.x86_64.rpm kernel-module-fuse-2.6.18-53.1.4.el5xen-2.6.3-1.el5.x86_64.rpm kernel-module-ndiswrapper-2.6.18-53.1.4.el5-1.41-1.SL.x86_64.rpm kernel-module-ndiswrapper-2.6.18-53.1.4.el5xen-1.41-1.SL.x86_64.rpm kernel-module-ndiswrapper-2.6.18-8.1.8.el5-1.49-1.SL.x86_64.rpm kernel-module-openafs-2.6.18-53.1.4.el5-1.4.4-42.SL5.x86_64.rpm kernel-module-openafs-2.6.18-53.1.4.el5-debuginfo-1.4.4-42.SL5.x86_64.rpm kernel-module-openafs-2.6.18-53.1.4.el5xen-1.4.4-42.SL5.x86_64.rpm kernel-module-openafs-2.6.18-53.1.4.el5xen-debuginfo-1.4.4-42.SL5.x86_64.rpm kernel-module-r1000-2.6.18-53.1.4.el5-1.05-1.sl.x86_64.rpm kernel-module-r1000-2.6.18-53.1.4.el5xen-1.05-1.sl.x86_64.rpm kmod-gfs-0.1.19-7.el5.1.x86_64.rpm kmod-gfs-xen-0.1.19-7.el5.1.x86_64.rpm -Connie Sieh -Troy Dawson . The recent kernel patch for Scientific Linux resolves several security vulnerabilities within the kernel, enhancing system stability.. Kernel Update, Security Advisory, Scientific Linux, Memory Exhaustion, DoS Threat. . LinuxSecurity.com Team

Calendar 2 Dec 03, 2007 Scientific Linux
91

Gentoo GLSA-200706-04 High: MadWifi Multiple Issues - DoS or Code Exec

Multiple vulnerabilities have been discovered in MadWifi, possibly allowing for the execution of arbitrary code or a Denial of Service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200706-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: MadWifi: Multiple vulnerabilities Date: June 11, 2007 Bugs: #179532 ID: 200706-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been discovered in MadWifi, possibly allowing for the execution of arbitrary code or a Denial of Service. Background ========= The MadWifi driver provides support for Atheros based IEEE 802.11 Wireless Lan cards. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-wireless/madwifi-ng < 0.9.3.1 > = 0.9.3.1 Description ========== Md Sohail Ahmad from AirTight Networks has discovered a divison by zero in the ath_beacon_config() function (CVE-2007-2830). The vendor has corrected an input validation error in the ieee80211_ioctl_getwmmparams() and ieee80211_ioctl_getwmmparams() functions(CVE-207-2831), and an input sanitization error when parsing nested 802.3 Ethernet frame lengths (CVE-2007-2829). Impact ===== An attacker could send specially crafted packets to a vulnerable host to exploit one of these vulnerabilities, possibly resulting in the execution of arbitrary code with root privileges, or a Denial of Service. Workaround ========= There is no known workaround at this time. Resolution ========= All MadWifi users should upgrade to the latestversion: # emerge --sync # emerge --ask --oneshot --verbose "> =net-wireless/madwifi-ng-0.9.3.1" References ========= [ 1 ] CVE-2007-2829 https://www.cve.org/CVERecord?id=CVE-2007-2829 [ 2 ] CVE-2007-2830 https://www.cve.org/CVERecord?id=CVE-2007-2830 [ 3 ] CVE-2007-2831 https://www.cve.org/CVERecord?id=CVE-2007-2831 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200706-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2007 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Critical warning issued concerning MadWifi security flaws on Gentoo systems, possibly leading to unauthorized code execution or denial of service.. MadWifi Security Advisory, Gentoo Linux Updates, High Severity Vulnerabilities, Wireless LAN Security. . LinuxSecurity.com Team

Calendar 2 Jun 11, 2007 Gentoo
89

Fedora Core 5: 2006-256 Moderate: wpa_supplicant Driver Support Fix

Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-256 2006-03-30 ---------------------------------------------------------------------Product : Fedora Core 5 Name : wpa_supplicant Version : 0.4.8 Release : 6.fc5 Summary : WPA/WPA2/IEEE 802.1X Supplicant Description : wpa_supplicant is a WPA Supplicant for Linux, BSD and Windows with support for WPA and WPA2 (IEEE 802.11i / RSN). Supplicant is the IEEE 802.1X/WPA component that is used in the client stations. It implements key negotiation with a WPA Authenticator and it controls the roaming and IEEE 802.11 authentication/association of the wlan driver. ---------------------------------------------------------------------Update Information: This update to wpa_supplicant provides: - Fixes for Orinoco-based wireless cards - Addition of the Prism54 (fullmac) WPA driver - Removal of the deprecated 'ipw' WPA driver, Intel Pro/Wireless users should use the 'wext' driver instead ---------------------------------------------------------------------* Mon Mar 27 2006 Dan Williams - 0.4.8-6 - Add patch to make orinoco happy with WEP keys - Enable Prism54-specific driver - Disable ipw-specific driver; ipw2x00 should be using WEXT instead ---------------------------------------------------------------------This update can be downloaded from: 80d6f1325f5df935dab6ee7d7da773fbe8998c27 SRPMS/wpa_supplicant-0.4.8-6.fc5.src.rpm a490f96ef48adaa1b8567c0ba9292bc6d16aca1b ppc/wpa_supplicant-0.4.8-6.fc5.ppc.rpm f0df53ce4ac2da2d576909c562541cb449600c7e ppc/wpa_supplicant-gui-0.4.8-6.fc5.ppc.rpm e7428397df6d9341e843d9cc18dd4b3c684e18e7 ppc/debug/wpa_supplicant-debuginfo-0.4.8-6.fc5.ppc.rpm 16d1d1c95effe972df8d56a358fd364ba1e40528 x86_64/wpa_supplicant-0.4.8-6.fc5.x86_64.rpm aa3386fac43cf5846e54471ba46d9935aa8e2f14 x86_64/wpa_supplicant-gui-0.4.8-6.fc5.x86_64.rpm 5ff81ac301dde8da90fd491073b59b009f031c79 x86_64/debug/wpa_supplicant-debuginfo-0.4.8-6.fc5.x86_64.rpm 0cf38f1ee3d9e8d07103a851467dd5fb95e2d381 i386/wpa_supplicant-0.4.8-6.fc5.i386.rpm 6586ae4af583756b42f833d892f2d9acde121d63 i386/wpa_supplicant-gui-0.4.8-6.fc5.i386.rpm a2b4b4210b63bd5ae2b32a2a26c7ffb70b7e25d6 i386/debug/wpa_supplicant-debuginfo-0.4.8-6.fc5.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance your Fedora Core 5 with improved driver support for WPA/WPA2 in the latest wpa_supplicant update.. Fedora Core 5,wpa_supplicant update,network security. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 30, 2006 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here